Critical

Tycon Systems TPDIN-Monitor-WEB3

All CISA Advisories

Overview

Tycon Systems has identified several vulnerabilities in its TPDIN-Monitor-WEB3 device, affecting versions 2.2.9 and earlier. These vulnerabilities could allow attackers to conduct man-in-the-middle attacks, perform factory resets, or access sensitive information due to hard-coded credentials, cross-site request forgery (CSRF), and missing authorization. The CVEs associated with these issues are CVE-2026-77847, CVE-2026-82712, and CVE-2026-82684, with severity ratings ranging from medium to high. Tycon Systems has released a firmware update, version 2.4.2, which addresses these vulnerabilities. Users still operating on the older version are urged to upgrade promptly to enhance their security posture and protect against potential exploits.

Key Takeaways

  • Affected Systems: Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior; CVEs: CVE-2026-77847, CVE-2026-82712, CVE-2026-82684.
  • Action Required: Users should upgrade to TPDIN-Monitor-WEB3 Firmware v2.
  • Timeline: Newly disclosed

Original Article Summary

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site Request Forgery (CSRF), Missing Authorization Background Critical Infrastructure Sectors: Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-77847 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Use of Hard-coded Credential vulnerability. This could allow an attacker to intercept sensitive information or credentials. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB3 Vendor: Tycon Systems Product Version: Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9 Product Status: known_affected Remediations Vendor fix Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Mitigation Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw Mitigation All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex Mitigation A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. Mitigation For more information, contact Tycon Systems: https://www.tyconsystems.com/contact Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.5 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 7.1 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-82712 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Cross-Site Request Forgery vulnerability. This could allow an attacker to perform state changing operations on the device. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB3 Vendor: Tycon Systems Product Version: Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9 Product Status: known_affected Remediations Vendor fix Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Mitigation Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw Mitigation All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex Mitigation A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. Mitigation For more information, contact Tycon Systems: https://www.tyconsystems.com/contact Relevant CWE: CWE-352 Cross-Site Request Forgery (CSRF) Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-82684 Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents. View CVE Details Affected Products Tycon Systems TPDIN-Monitor-WEB3 Vendor: Tycon Systems Product Version: Tycon Systems TPDIN-Monitor-WEB3: <=2.2.9 Product Status: known_affected Remediations Vendor fix Tycon Systems has released TPDIN-Monitor-WEB3 Firmware v2.4.2. Mitigation Units already running v2.4.2, for subsequent updates (signed container): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2.tfw Mitigation All units currently in the field, including the v2.2.9 covered by this report (legacy Intel HEX): https://firm.tyconsystems.com/tpdin-monitor-web3-v2/TPDIN-MONITOR-WEB3-V2_v2.4.2T.hex Mitigation A unit running v2.2.9 installs the .hex build directly and arrives at v2.4.2 in a single step; no intermediate version is required. The signed .tfw container cannot be read by a v2.2.9 updater, which accepts only Intel HEX, so the .hex artifact is the one every deployed unit needs. Mitigation For more information, contact Tycon Systems: https://www.tyconsystems.com/contact Relevant CWE: CWE-862 Missing Authorization Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N 4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Acknowledgments Abdiwelli Guled reported these vulnerabilities to CISA. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolating them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. CISA also recommends users take the following measures to protect themselves from social engineering attacks: Do not click web links or open attachments in unsolicited email messages. Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams. Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks. No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. Revision History Initial Release Date: 2026-09-03 Date Revision Summary 2026-09-03 1 Initial Publication Legal Notice and Terms of Use

Impact

Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior; CVEs: CVE-2026-77847, CVE-2026-82712, CVE-2026-82684.

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Newly disclosed

Remediation

Users should upgrade to TPDIN-Monitor-WEB3 Firmware v2.4.2. For units running v2.2.9, the .hex build must be installed directly to reach v2.4.2 in a single step. The links for both the signed container and the legacy Intel HEX are provided for this update.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, CVE, Vulnerability, and 3 more.

Related Coverage

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The Hacker News

A North Korean hacking group known as Jade Sleet has been linked to a breach involving a smaller Indian IT services firm. Cybersecurity researchers from SentinelOne reported that the attackers used sophisticated backdoors named FLATROOF and ROOFDECK to infiltrate the organization. The breach underscores the ongoing strategy of targeting smaller developers, which can provide access to larger networks. This incident raises concerns about the security practices of IT service providers, as they often hold sensitive information that could be exploited in further attacks. Companies in the tech sector should reassess their security measures to prevent similar breaches.

Sep 21, 2026

Intent injection attacks are a new worry for AI-native 6G networks

Help Net Security

Researchers from the University of Ottawa and Nokia Bell Labs have raised concerns about a new type of cybersecurity threat specifically targeting AI-native 6G networks. This threat, known as adversarial intent injection, takes advantage of the intent-based networking (IBN) approach, which allows operators to define desired outcomes while the software translates these into network policies. The researchers argue that this abstraction could give attackers greater opportunities to exploit vulnerable APIs. They tested two machine-learning detectors against this type of attack, indicating that the issue is serious enough to warrant further investigation and solutions. As 6G technology continues to develop, it’s crucial for network operators to address these vulnerabilities to safeguard against potential malicious actions.

Sep 21, 2026

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Help Net Security

A recent survey by Sapio Research revealed that 40% of large companies faced issues related to AI compliance or governance in the last year. The survey involved 1,000 senior leaders in IT, operations, and transformation. A significant 84% of these incidents were linked to problems in existing workflows, which were often designed for human involvement. These workflows included manual approvals and handoffs, making them incompatible with the automated nature of AI. This situation raises concerns about how companies integrate AI into their processes, highlighting the need for better alignment between technology and workflow design to mitigate compliance risks.

Sep 21, 2026

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities in the Linux Kernel to its Known Exploited Vulnerabilities catalog. This update indicates that these flaws have been identified as actively exploited in the wild, posing risks to various systems that rely on the Linux operating system. While specific details on the nature of the exploits are not currently available, the inclusion of these vulnerabilities in the catalog signals a need for immediate attention from system administrators and security teams. Users and organizations utilizing affected Linux versions should prioritize patching their systems to mitigate potential attacks, as these vulnerabilities could be leveraged by attackers for unauthorized access or other malicious activities. Staying updated with the latest patches is crucial for maintaining system security.

Sep 20, 2026

Malicious npm packages evade install-script defenses at runtime

BleepingComputer

A new malware campaign is targeting users of the npm package manager, specifically through a malicious package named 'indexed-btree'. Unlike traditional attacks that insert harmful code into installation scripts, this campaign cleverly embeds malicious behavior within the normal runtime operations of the package. This method allows attackers to bypass common security defenses that monitor installation scripts. As a result, developers who unknowingly install this package could face serious security risks, including potential data breaches or system compromise. It’s crucial for developers to be vigilant and scrutinize the packages they use, as traditional safeguards may not catch these types of attacks.

Sep 20, 2026

AI Hallucinations Nearly Triggered a US-China Military Confrontation

Security Affairs

An AI-generated intelligence report nearly escalated tensions between the US and China during the Iran war by falsely claiming that a Chinese ship was transporting nuclear weapons components. According to sources cited by CNN, this misleading report circulated among US military officials, prompting discussions about a potential military operation in response. Fortunately, the situation was defused before any action was taken. This incident raises serious concerns about the reliability of AI in military intelligence and the potential for misinformation to provoke international conflict. As AI technology becomes more integrated into defense systems, ensuring accuracy and accountability in its outputs is crucial to prevent dangerous misunderstandings.

Sep 20, 2026